CVE-2023-43669
published 2023-09-21CVE-2023-43669: The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.62%
73.7th percentile
The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rust-tungstenite | < rust-tungstenite 0.20.1-1 (forky) | rust-tungstenite 0.20.1-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| snapview | tungstenite | <= 0.20.0 | — |
| snapview | tungstenite | >= 0 < 0.20.1 | 0.20.1 |
| snapview | tungstenite | >= 0.0.0-0 < 0.20.1 | 0.20.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface
ghsa·2024-01-19·CVSS 7.5
[HIGH] SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface
SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface
SurrealDB depends on the `tungstenite` and `tokio-tungstenite` crates used by the `axum` crate, which handles connections to the SurrealDB WebSocket interface. On versions before `0.20.1`, the `tungstenite` crate presented an issue which allowed the parsing of HTTP headers during the client handshake to continuously consume high CPU when the headers were very long. All affected crates have been updated in SurrealDB version `1.1.0`.
From the original advisory for [CVE-2023-43669](https://nvd.nist.gov/vuln/detail/CVE-2023-43669):
"The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client hand
OSV
SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface
osv·2024-01-19·CVSS 7.5
[HIGH] SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface
SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket Interface
SurrealDB depends on the `tungstenite` and `tokio-tungstenite` crates used by the `axum` crate, which handles connections to the SurrealDB WebSocket interface. On versions before `0.20.1`, the `tungstenite` crate presented an issue which allowed the parsing of HTTP headers during the client handshake to continuously consume high CPU when the headers were very long. All affected crates have been updated in SurrealDB version `1.1.0`.
From the original advisory for [CVE-2023-43669](https://nvd.nist.gov/vuln/detail/CVE-2023-43669):
"The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client hand
OSV
Tungstenite allows remote attackers to cause a denial of service
osv·2023-09-25
CVE-2023-43669 Tungstenite allows remote attackers to cause a denial of service
Tungstenite allows remote attackers to cause a denial of service
The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause
a denial of service (minutes of CPU consumption) via an excessive length of an
HTTP header in a client handshake. The length affects both how many times a parse
is attempted (e.g., thousands of times) and the average amount of data for each
parse attempt (e.g., millions of bytes).
GHSA
Tungstenite allows remote attackers to cause a denial of service
ghsa·2023-09-21
CVE-2023-43669 [HIGH] CWE-400 Tungstenite allows remote attackers to cause a denial of service
Tungstenite allows remote attackers to cause a denial of service
The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
OSV
Tungstenite allows remote attackers to cause a denial of service
osv·2023-09-21
CVE-2023-43669 [HIGH] Tungstenite allows remote attackers to cause a denial of service
Tungstenite allows remote attackers to cause a denial of service
The Tungstenite crate through 0.20.0 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
OSV
CVE-2023-43669: The Tungstenite crate before 0
osv·2023-09-21·CVSS 7.5
CVE-2023-43669 [HIGH] CVE-2023-43669: The Tungstenite crate before 0
The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
Debian
CVE-2023-43669: rust-tungstenite - The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a ...
vendor_debian·2023·CVSS 7.5
CVE-2023-43669 [HIGH] CVE-2023-43669: rust-tungstenite - The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a ...
The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
Scope: local
forky: resolved (fixed in 0.20.1-1)
sid: resolved (fixed in 0.20.1-1)
trixie: resolved (fixed in 0.20.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2240110https://bugzilla.suse.com/show_bug.cgi?id=1215563https://crates.io/crates/tungstenite/versionshttps://cwe.mitre.org/data/definitions/407.htmlhttps://github.com/advisories/GHSA-9mcr-873m-xcxphttps://github.com/github/advisory-database/pull/2752https://github.com/snapview/tungstenite-rs/commit/8b3ecd3cc0008145ab4bc8d0657c39d09db8c7e2https://github.com/snapview/tungstenite-rs/issues/376https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R77EUWPZVP5WSMNXUXUDNHR7G7OI5NGM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/THK6G6CD4VW6RCROWUV2C4HSINKK3XAK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT7SF6CQ5VHAGFLWNXY64NFSW4WIWE7D/https://security-tracker.debian.org/tracker/CVE-2023-43669https://bugzilla.redhat.com/show_bug.cgi?id=2240110https://bugzilla.suse.com/show_bug.cgi?id=1215563https://crates.io/crates/tungstenite/versionshttps://cwe.mitre.org/data/definitions/407.htmlhttps://github.com/advisories/GHSA-9mcr-873m-xcxphttps://github.com/github/advisory-database/pull/2752https://github.com/snapview/tungstenite-rs/commit/8b3ecd3cc0008145ab4bc8d0657c39d09db8c7e2https://github.com/snapview/tungstenite-rs/issues/376https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R77EUWPZVP5WSMNXUXUDNHR7G7OI5NGM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/THK6G6CD4VW6RCROWUV2C4HSINKK3XAK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT7SF6CQ5VHAGFLWNXY64NFSW4WIWE7D/https://security-tracker.debian.org/tracker/CVE-2023-43669
2023-09-21
Published